Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Very basic interface question

    Scheduled Pinned Locked Moved General pfSense Questions
    15 Posts 4 Posters 1.4k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      BugMan
      last edited by

      Hello all,

      My apologies for the very basic question here, I'm brand spanking new to PFsense and feeling a bit lost. I want to set specific interface assignments (Static IP, DHCP servers, VLANs, firewall rules between interfaces, etc) and would appreciate some help.

      I've run through the inital setup wizard and am able to play around in the GUI. I want to set specific configurations on each of my LAN interfaces instead of leaving them in a generic switch configuration.

      However I only see WAN and LAN interfaces in the Interface Assignments page, and no option to add more interfaces. I see a warning stating that members of a lagg will not be shown in interface assignment, but there's no configuration of any kind under the LAGG tab.

      What am I missing? I'm used to Fortinet gear and would typically have to remove the interfaces from being in the generic switch group to accomplish something similar, but I'm not seeing that here.

      Thanks so much for any help!

      NogBadTheBadN 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN Offline
        NogBadTheBad @BugMan
        last edited by

        @bugman Have you created the VLANS ?

        Screenshot 2021-11-17 at 16.40.30.png

        Do they appear under Interface Assignments ?

        Screenshot 2021-11-17 at 16.41.45.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • B Offline
          BugMan
          last edited by

          I'm trying to create physical interfaces first, then will create VLANs for some of the interfaces. I don't have the option / button to add new interfaces in the Interfaces Assignments tab.

          There's just the WAN and LAN interfaces. I have an option to Delete the LAN interface. Plus a Save button. There is no green Add button, like in your screenshot.

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN Offline
            NogBadTheBad @BugMan
            last edited by NogBadTheBad

            @bugman

            What hardware do you have ?

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • B Offline
              BugMan
              last edited by

              A Netgate 2100. 4 LAN ports and a WAN.

              NogBadTheBadN 1 Reply Last reply Reply Quote 0
              • NogBadTheBadN Offline
                NogBadTheBad @BugMan
                last edited by NogBadTheBad

                @bugman Ah the interfaces are switch ports, sorry but I don't have a 2100.

                My 4860 has individual network ports.

                Calling @johnpoz 😁

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                1 Reply Last reply Reply Quote 0
                • B Offline
                  BugMan
                  last edited by

                  Is there a way to change them from switch to network?

                  NogBadTheBadN johnpozJ 2 Replies Last reply Reply Quote 0
                  • NogBadTheBadN Offline
                    NogBadTheBad @BugMan
                    last edited by

                    @bugman

                    https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/switch-overview.html

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    1 Reply Last reply Reply Quote 3
                    • johnpozJ Online
                      johnpoz LAYER 8 Global Moderator @BugMan
                      last edited by

                      @bugman yeah can for sure assign ports from the switch to specific vlans..

                      https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/switch-overview.html

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      johnpozJ 1 Reply Last reply Reply Quote 2
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator @johnpoz
                        last edited by

                        @NogBadTheBad - quicker than me ;)

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • B Offline
                          BugMan
                          last edited by

                          Thanks for the guide, fellas! I really appreciate it.

                          I have to say, though...That was not intuitive! Gotta create a VLAN and navigate through half a dozen submenus just to create a port with a static IP.

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ Online
                            johnpoz LAYER 8 Global Moderator @BugMan
                            last edited by

                            @bugman well yeah its a switch, so only way to do it is via vlan..

                            If you had discrete interfaces ;) I personally see no point to switch ports on a router.. Give me discrete all the time.. I have a sg4860 at home..

                            But I have to say the switch ports in the 3100 did come in a bit handy in one of the setups I have at one of our remote offices.. Saved me from having to use a switch ;) So depending on your needs or requirements.. But in general I would choose interfaces over switch ports any day for my router..

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • B Offline
                              BugMan
                              last edited by

                              I'm stumped yet again. How do I enable trunking on an interface? I want one of my ports to allow multiple VLANs, while another port doesn't have tagged traffic coming into it.

                              When I try to assign a VLAN to a specific port in Interface Assignment I get the error:
                              This Switch port is already in used by another interface.

                              johnpozJ 1 Reply Last reply Reply Quote 0
                              • johnpozJ Online
                                johnpoz LAYER 8 Global Moderator @BugMan
                                last edited by

                                @bugman you need to edit the switch ports to carry what vlans you want.. Tagged or untagged you can have as many vlans you want on a port. Only 1 vlan can be untagged though, all others would need to be tagged.

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S Offline
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  @bugman said in Very basic interface question:

                                  When I try to assign a VLAN to a specific port in Interface Assignment I get the error:
                                  This Switch port is already in used by another interface.

                                  That setting in the main interface config does not configure the switch. Instead that is used to have the VLAN interface status reflect the port status. So for example if you have a VLAN assign as OPT1 and the switch is configured to have port 4 as an access port for that VLAN, you can set port 4 there so that OPT shows as DOWN when port 4 is disconnected.

                                  What you need to do to trunk a VLAN to a port is set that in the switch config. Like:

                                  Screenshot from 2021-11-17 23-36-11.png

                                  That will make a VLAN created in LAN, mvneta1.100, available tagged on port 4.

                                  You need to be sure to set in the internal port, 5, also tagged as shown there for all VLANs you need.

                                  Steve

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.